Windows Analysis Report https://create.piktochart.com/output/55231820-voir-le-document-complet

Overview

General Information

Sample URL: https://create.piktochart.com/output/55231820-voir-le-document-complet
Analysis ID: 452740
Infos:

Most interesting Screenshot:

Detection

HTMLPhisher
Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Yara detected HtmlPhish29

Classification

AV Detection:

barindex
Antivirus / Scanner detection for submitted sample
Source: https://create.piktochart.com/output/55231820-voir-le-document-complet SlashNext: detection malicious, Label: Fake Login Page type: Phishing & Social Engineering

Phishing:

barindex
Yara detected HtmlPhish29
Source: Yara match File source: 08074.pages.csv, type: HTML
Source: Yara match File source: 58006.pages.csv, type: HTML
Source: Yara match File source: 06665.pages.csv, type: HTML
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Source: unknown HTTPS traffic detected: 104.17.211.204:443 -> 192.168.2.5:49720 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.71.176:443 -> 192.168.2.5:49733 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.115.176:443 -> 192.168.2.5:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.234.204:443 -> 192.168.2.5:49736 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.234.204:443 -> 192.168.2.5:49737 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.71.176:443 -> 192.168.2.5:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.115.176:443 -> 192.168.2.5:49739 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.244.42.8:443 -> 192.168.2.5:49749 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.13.189:443 -> 192.168.2.5:49763 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.71.238:443 -> 192.168.2.5:49767 version: TLS 1.2
Source: Reporting and NEL.4.dr String found in binary or memory: #chttpswww.facebook.com equals www.facebook.com (Facebook)
Source: Reporting and NEL.4.dr String found in binary or memory: coop_reporthttps://www.facebook.com/browser_reporting/ equals www.facebook.com (Facebook)
Source: Reporting and NEL.4.dr String found in binary or memory: coop_reporthttps://www.facebook.com/browser_reporting/ equals www.facebook.com (Facebook)
Source: Current Session.1.dr String found in binary or memory: https://www.facebook.com/v2.0/plugins/comments.php?app_id=360137457436393&channel=https%3A%2F%2Fstaticxx.facebook.com%2Fx%2Fconnect%2Fxd_arbiter%2F%3Fversion%3D46%23cb%3Df146defd036afac%26domain%3Dcreate.piktochart.com%26origin%3Dhttps%253A%252F%252Fcreate.piktochart.com%252Ff363b0f8378c408%26relation%3Dparent.parent&container_width=849&height=100&href=https%3A%2F%2Fcreate.piktochart.com%2Foutput%2F55231820-voir-le-document-complet&locale=en_US&sdk=joey&version=v2.0&width=800 equals www.facebook.com (Facebook)
Source: Current Session.1.dr String found in binary or memory: https://www.facebook.com/v2.0/plugins/like.php?action=like&app_id=360137457436393&channel=https%3A%2F%2Fstaticxx.facebook.com%2Fx%2Fconnect%2Fxd_arbiter%2F%3Fversion%3D46%23cb%3Df13e597513e9cd%26domain%3Dcreate.piktochart.com%26origin%3Dhttps%253A%252F%252Fcreate.piktochart.com%252Ff363b0f8378c408%26relation%3Dparent.parent&container_width=0&font=arial&height=25&href=https%3A%2F%2Fcreate.piktochart.com%2Foutput%2F55231820-voir-le-document-complet&layout=button_count&locale=en_US&sdk=joey&send=false&share=false&show_faces=false&width=90 equals www.facebook.com (Facebook)
Source: Reporting and NEL.4.dr String found in binary or memory: httpswww.facebook.com equals www.facebook.com (Facebook)
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: {"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://www.google.com","supports_spdy":true},{"isolation":[],"server":"https://ssl.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://www.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://apis.google.com","supports_spdy":true},{"isolation":[],"server":"https://ogs.google.com","supports_spdy":true},{"isolation":[],"server":"https://dns.google","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13274072572347334","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://redirector.gvt1.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13274072572348316","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://accounts.google.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13274072572592844","port":443,"protocol_str":"quic"},{"advertised_versions":[50],"expiration":"13274072572592850","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://r2---sn-h0jeener.gvt1.com"},{"isolation":[],"server":"https://js.hs-scripts.com","supports_spdy":true},{"isolation":[],"server":"https://assets.pinterest.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13274072573064592","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://www.googletagmanager.com","supports_spdy":true},{"isolation":[],"server":"https://z.moatads.com","supports_spdy":true},{"isolation":[],"server":"https://a.nel.cloudflare.com","supports_spdy":true},{"isolation":[],"server":"https://js.hsleadflows.net","supports_spdy":true},{"isolation":[],"server":"https://js.hs-analytics.net","supports_spdy":true},{"isolation":[],"server":"https://js.hsadspixel.net","supports_spdy":true},{"isolation":[],"server":"https://connect.facebook.net","supports_spdy":true},{"isolation":[],"server":"https://fonts.piktochart.com","supports_spdy":true},{"isolation":[],"server":"https://s7.addthis.com","supports_spdy":true},{"isolation":[],"server":"https://api-public.addthis.com","supports_spdy":true},{"isolation":[],"server":"https://www.facebook.com","supports_spdy":true},{"isolation":[],"server":"https://track.hubspot.com","supports_spdy":true},{"isolation":[],"server":"https://js.hs-banner.com","supports_spdy":true},{"isolation":[],"server":"https://beacon-v2.helpscout.net","supports_spdy":true},{"isolation":[],"server":"https://syndication.twitter.com","supports_spdy":true},{"isolation":[],"server":"https://create.piktochart.com","supports_spdy":true},{"isolation":[],"server":"https://d3hb14vkzrxvla.cloudfront.net","supports_spdy":true},{"isolation":[],"server":"https://forms.hubspot.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13274072587581116","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://clients2.googleusercontent.com","suppo
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: {"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://www.google.com","supports_spdy":true},{"isolation":[],"server":"https://ssl.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://www.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://apis.google.com","supports_spdy":true},{"isolation":[],"server":"https://ogs.google.com","supports_spdy":true},{"isolation":[],"server":"https://dns.google","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13274072572347334","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://redirector.gvt1.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13274072572348316","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://accounts.google.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13274072572592844","port":443,"protocol_str":"quic"},{"advertised_versions":[50],"expiration":"13274072572592850","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://r2---sn-h0jeener.gvt1.com"},{"isolation":[],"server":"https://js.hs-scripts.com","supports_spdy":true},{"isolation":[],"server":"https://assets.pinterest.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13274072573064592","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://www.googletagmanager.com","supports_spdy":true},{"isolation":[],"server":"https://z.moatads.com","supports_spdy":true},{"isolation":[],"server":"https://a.nel.cloudflare.com","supports_spdy":true},{"isolation":[],"server":"https://js.hsleadflows.net","supports_spdy":true},{"isolation":[],"server":"https://js.hs-analytics.net","supports_spdy":true},{"isolation":[],"server":"https://js.hsadspixel.net","supports_spdy":true},{"isolation":[],"server":"https://connect.facebook.net","supports_spdy":true},{"isolation":[],"server":"https://fonts.piktochart.com","supports_spdy":true},{"isolation":[],"server":"https://s7.addthis.com","supports_spdy":true},{"isolation":[],"server":"https://api-public.addthis.com","supports_spdy":true},{"isolation":[],"server":"https://www.facebook.com","supports_spdy":true},{"isolation":[],"server":"https://track.hubspot.com","supports_spdy":true},{"isolation":[],"server":"https://js.hs-banner.com","supports_spdy":true},{"isolation":[],"server":"https://beacon-v2.helpscout.net","supports_spdy":true},{"isolation":[],"server":"https://syndication.twitter.com","supports_spdy":true},{"isolation":[],"server":"https://create.piktochart.com","supports_spdy":true},{"isolation":[],"server":"https://d3hb14vkzrxvla.cloudfront.net","supports_spdy":true},{"isolation":[],"server":"https://forms.hubspot.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13274072587581116","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://clients2.googleusercontent.com","suppo
Source: unknown DNS traffic detected: queries for: clients2.google.com
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://a.nel.cloudflare.com
Source: Reporting and NEL.4.dr String found in binary or memory: https://a.nel.cloudflare.com/report/v3?s=5IF%2Bghr6csx52DsAmrAbRXJrcRcpo%2BVh250eW%2Bj9NniPB3FArGmg6
Source: Reporting and NEL.4.dr String found in binary or memory: https://a.nel.cloudflare.com/report/v3?s=Dpom3ejcsjx3ri8FvujfYK6Jog83WFceuzyDWun1q6HCuHCz2luTuPSgqjq
Source: Reporting and NEL.4.dr String found in binary or memory: https://a.nel.cloudflare.com/report/v3?s=SjvZWKEeWmafluVFV4OmxKmQqWvcFbNioBjjZaOrLNSjEXjYZHRlLGdBpEN
Source: Reporting and NEL.4.dr String found in binary or memory: https://a.nel.cloudflare.com/report/v3?s=SrEqmE0RArYXFTxkrz18FfTuLmfJMlzTDzuXpnMtgWpjaXi99CbSEWJrxeW
Source: Reporting and NEL.4.dr String found in binary or memory: https://a.nel.cloudflare.com/report/v3?s=cVeamK9%2BzE%2FXKaKII%2Bec4c%2Blh1ckBD6ibuDrf6WGQtqqZYcfKSZ
Source: Reporting and NEL.4.dr String found in binary or memory: https://a.nel.cloudflare.com/report/v3?s=ok6DoTxOvKrr36f3FRk9FOD%2FsL6Uc3pk2oIvOin5teE4pexrYrlzlwnjx
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr, manifest.json0.1.dr, 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://accounts.google.com
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://api-public.addthis.com
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr, manifest.json0.1.dr, 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://apis.google.com
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://assets.pinterest.com
Source: ddd24a849a7d969b_0.1.dr String found in binary or memory: https://beacon-v2.helpscout.net/static/js/main.8d8df292.js
Source: dd6f4ba140e73b7c_0.1.dr String found in binary or memory: https://beacon-v2.helpscout.net/static/js/vendor.3987c6ee.js
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.1.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://connect.facebook.net
Source: 9be232425752a77d_0.1.dr String found in binary or memory: https://connect.facebook.net/en_US/fbevents.js
Source: 21c18fb9ca077705_0.1.dr String found in binary or memory: https://connect.facebook.net/en_US/sdk.js
Source: 27958a9e606be339_0.1.dr String found in binary or memory: https://connect.facebook.net/en_US/sdk.js?hash=67f66cc8858252eee8f3c709fecb9e55
Source: 4149c5502c3a6381_0.1.dr String found in binary or memory: https://connect.facebook.net/signals/config/1376538882436128?v=2.9.43&r=stable
Source: manifest.json0.1.dr String found in binary or memory: https://content.googleapis.com
Source: 000003.log3.1.dr String found in binary or memory: https://create.piktochart.com
Source: Current Session.1.dr, 000003.log0.1.dr String found in binary or memory: https://create.piktochart.com/
Source: 4f316a51b12971ff_0.1.dr String found in binary or memory: https://create.piktochart.com/assets/0-12328b9d54bdab438f26-bundle.js
Source: fe39d35c85990904_0.1.dr String found in binary or memory: https://create.piktochart.com/assets/1-fa45cb67e5e65f3b8807-bundle.js
Source: ab74d73a1ef97342_0.1.dr String found in binary or memory: https://create.piktochart.com/assets/50-96e7d07fdff0911b44a2-bundle.js
Source: dd7f95b54e3ba22e_0.1.dr String found in binary or memory: https://create.piktochart.com/assets/6-d91ac5ca25e3adc1ca9a-bundle.js
Source: db4b65f7477f4e6b_0.1.dr String found in binary or memory: https://create.piktochart.com/assets/7-33479796fc828dbb502d-bundle.js
Source: 2fe82c74fd70b364_0.1.dr String found in binary or memory: https://create.piktochart.com/assets/82-09a41c0d0089928b860f-bundle.js
Source: b6b3d5da9b0df756_0.1.dr String found in binary or memory: https://create.piktochart.com/assets/magic-9602756920677fa84a49-bundle.js
Source: 65e6498e539a29eb_0.1.dr String found in binary or memory: https://create.piktochart.com/assets/runtime~magic-bundle-f36cc413ca689855c72c.js
Source: 8dbfa43630072d16_0.1.dr String found in binary or memory: https://create.piktochart.com/assets/shared/module/oldie-browser-8dd053866fb9c0f8595e7ecc8a15a1f1d15
Source: Favicons.1.dr String found in binary or memory: https://create.piktochart.com/favicon.png
Source: 000003.log3.1.dr String found in binary or memory: https://create.piktochart.com/output/55231820-voir-le-document-complet
Source: History Provider Cache.1.dr String found in binary or memory: https://create.piktochart.com/output/55231820-voir-le-document-complet23VOIR
Source: Current Session.1.dr String found in binary or memory: https://create.piktochart.com/output/55231820-voir-le-document-complet3VOIR
Source: History.1.dr String found in binary or memory: https://create.piktochart.com/output/55231820-voir-le-document-completVOIR
Source: Current Session.1.dr String found in binary or memory: https://create.piktochart.comh
Source: Reporting and NEL.4.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/downloads-lorry
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr, 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr, f9be0920-44a8-41f4-93e8-e3dd8dc6477b.tmp.4.dr, 5a776fe8-c5e7-412a-aa9a-00022882cdd5.tmp.4.dr String found in binary or memory: https://dns.google
Source: manifest.json0.1.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.1.dr String found in binary or memory: https://fonts.googleapis.com;
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.1.dr String found in binary or memory: https://fonts.gstatic.com;
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://fonts.piktochart.com
Source: manifest.json0.1.dr String found in binary or memory: https://hangouts.google.com/
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://js.hs-analytics.net
Source: 084bef842f7a1f6c_0.1.dr String found in binary or memory: https://js.hs-analytics.net/analytics/1626974400000/8163022.js
Source: 4827d11ed506017d_0.1.dr String found in binary or memory: https://js.hs-banner.com/8163022.js
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://js.hs-scripts.com
Source: f53bc223cfda59dd_0.1.dr String found in binary or memory: https://js.hs-scripts.com/8163022.js
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://js.hsadspixel.net
Source: 43f2fe14e13bce26_0.1.dr String found in binary or memory: https://js.hsadspixel.net/fb.js
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://js.hsleadflows.net
Source: 21c843c2c4bf3dca_0.1.dr String found in binary or memory: https://js.hsleadflows.net/leadflows.js
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr, 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json.1.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: dd6f4ba140e73b7c_0.1.dr, 21c843c2c4bf3dca_0.1.dr, 4f316a51b12971ff_0.1.dr, 38f7fc15f7830d68_0.1.dr String found in binary or memory: https://piktochart.com/
Source: 71c6bfad12ed3bc2_0.1.dr String found in binary or memory: https://piktochart.com/5n?
Source: 91c01328c9fc2b6d_0.1.dr String found in binary or memory: https://piktochart.com/9u3
Source: 65e6498e539a29eb_0.1.dr String found in binary or memory: https://piktochart.com/L
Source: 27958a9e606be339_0.1.dr String found in binary or memory: https://piktochart.com/Q
Source: 000003.log3.1.dr String found in binary or memory: https://piktochart.com/blog/11-2020-release-introducing-two-factor-authentication-and-saml/
Source: 000003.log3.1.dr String found in binary or memory: https://piktochart.com/blog/introducing-tables/
Source: 000003.log3.1.dr String found in binary or memory: https://piktochart.com/blog/piktostory-launch/
Source: 000003.log3.1.dr String found in binary or memory: https://piktochart.com/blog/product-updates-did-someone-say-new-features/
Source: 000003.log3.1.dr String found in binary or memory: https://piktochart.com/blog/video-storytelling-for-everyone/
Source: f00c39eff1ea5177_0.1.dr String found in binary or memory: https://piktochart.com/i
Source: 084bef842f7a1f6c_0.1.dr String found in binary or memory: https://piktochart.com/k
Source: 1d263bb56d0ae389_0.1.dr String found in binary or memory: https://piktochart.com/r
Source: f53bc223cfda59dd_0.1.dr String found in binary or memory: https://piktochart.com/tC4
Source: 000003.log3.1.dr String found in binary or memory: https://piktochart.com/wp-content/uploads/2020/02/Update-February20-1920x1080-1-300x169.png
Source: 000003.log3.1.dr String found in binary or memory: https://piktochart.com/wp-content/uploads/2020/10/Update-October20-1920x1080-1-300x169.png
Source: 000003.log3.1.dr String found in binary or memory: https://piktochart.com/wp-content/uploads/2020/11/Product-Update-1920x1080-1-300x169.png
Source: 000003.log3.1.dr String found in binary or memory: https://piktochart.com/wp-content/uploads/2021/04/April-product-update-blog-cover-300x169.png
Source: 000003.log3.1.dr String found in binary or memory: https://piktochart.com/wp-content/uploads/2021/05/Product-Update-May-300x169.png
Source: d7f4fb9b5d8e2e09_0.1.dr String found in binary or memory: https://platform.twitter.com/js/button.5573c974dc31bbdab5ea7923a0bd5cf3.js
Source: 38f7fc15f7830d68_0.1.dr String found in binary or memory: https://platform.twitter.com/widgets.js
Source: Current Session.1.dr String found in binary or memory: https://platform.twitter.com/widgets/tweet_button.06c6ee58c3810956b7509218508c7b56.en.html#dnt=false
Source: Current Session.1.dr String found in binary or memory: https://platform.twitter.com/widgets/widget_iframe.06c6ee58c3810956b7509218508c7b56.html?origin=http
Source: Current Session.1.dr String found in binary or memory: https://prosalonbox.org//doc/weds/office
Source: Current Session.1.dr String found in binary or memory: https://prosalonbox.org//doc/weds/officePP;_W&/
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://r2---sn-h0jeener.gvt1.com
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://redirector.gvt1.com
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://s7.addthis.com
Source: 1d263bb56d0ae389_0.1.dr String found in binary or memory: https://s7.addthis.com/js/300/addthis_widget.js
Source: f00c39eff1ea5177_0.1.dr String found in binary or memory: https://s7.addthis.com/static/counter.d27508c102582d608697.js
Source: Current Session.1.dr String found in binary or memory: https://s7.addthis.com/static/sh.f48a1a04fe8dbf021b4cda1d.html#rand=0.36598255868471297&iit=16270069
Source: manifest.json.1.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr, 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://ssl.gstatic.com
Source: 8e2a1c4ca92f95b7_0.1.dr String found in binary or memory: https://stats.g.doubleclick.net/j/collect
Source: messages.json83.1.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json83.1.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: 8e2a1c4ca92f95b7_0.1.dr String found in binary or memory: https://tagassistant.google.com/
Source: 054373a4275cb454_0.1.dr, 8e2a1c4ca92f95b7_0.1.dr String found in binary or memory: https://www.google-analytics.com/analytics.js
Source: 8e2a1c4ca92f95b7_0.1.dr String found in binary or memory: https://www.google-analytics.com/analytics.jsaD
Source: 8e2a1c4ca92f95b7_0.1.dr String found in binary or memory: https://www.google-analytics.com/debug/bootstrap
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr, manifest.json0.1.dr, 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://www.google.com
Source: manifest.json.1.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.1.dr String found in binary or memory: https://www.google.com;
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.1.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.1.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.1.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.1.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.1.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://www.googletagmanager.com
Source: 91c01328c9fc2b6d_0.1.dr String found in binary or memory: https://www.googletagmanager.com/gtm.js?id=GTM-TZB2X4X&gtm_auth=JgKKw811eIFTYt99LuIllA&gtm_preview=e
Source: 6c0f0a54-4698-4368-a587-7f4398c42dcc.tmp.4.dr, 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.1.dr String found in binary or memory: https://www.gstatic.com;
Source: 1904eaf6-fb6e-4d14-96ad-e9a0b6d2f7eb.tmp.4.dr String found in binary or memory: https://z.moatads.com
Source: 71c6bfad12ed3bc2_0.1.dr String found in binary or memory: https://z.moatads.com/addthismoatframe568911941483/moatframe.js
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49781
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49781 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 49791 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49784 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 49777 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 49783 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49787 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49797 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49713
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49797
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49792
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49791
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 49792 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown HTTPS traffic detected: 104.17.211.204:443 -> 192.168.2.5:49720 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.71.176:443 -> 192.168.2.5:49733 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.115.176:443 -> 192.168.2.5:49734 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.234.204:443 -> 192.168.2.5:49736 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.234.204:443 -> 192.168.2.5:49737 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.71.176:443 -> 192.168.2.5:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.17.115.176:443 -> 192.168.2.5:49739 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.244.42.8:443 -> 192.168.2.5:49749 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.13.189:443 -> 192.168.2.5:49763 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.71.238:443 -> 192.168.2.5:49767 version: TLS 1.2
Source: classification engine Classification label: mal56.phis.win@44/254@31/28
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-60FA27F6-1678.pma Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\9e63025c-409b-470e-b075-9c8fbde5d74f.tmp Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://create.piktochart.com/output/55231820-voir-le-document-complet'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1644,17532982768526373494,12220488661392661405,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1700 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1644,17532982768526373494,12220488661392661405,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1700 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs